BayMark Health Services Notifies Patients About October Ransomware Attack
Texas-based BayMark Health Services, North America’s largest provider of substance use disorder treatment and recovery services and a provider of administrative services to BAART Programs, Healthcare Resource Centers, and MedMark Treatment Centers, has started notifying patients that some of their protected health information was compromised in a recent cyberattack. According to the patient notification letters, BayMark Health Services discovered the cyberattack on October 11, 2024, when its IT systems were disrupted. The forensic investigation confirmed that an unauthorized third party had access to its network for almost 3 weeks between September 24, 2024, and October 14, 2024. During that time, the threat actor accessed and acquired files containing patient data. BayMark Health Services has reviewed the affected files and confirmed that they contained information such as patient names, dates of birth, services received, dates of service, Social Security numbers, driver’s license numbers, health insurance information, diagnostic and treatment information, and treating provider...
Patch Warning: Critical Ivanti Connect Secure Zero-day Exploited
Ivanti has released patches for two Connect Secure vulnerabilities including a critical zero-day remote code execution vulnerability that is being actively exploited in the wild to install malware. The first instances of exploitation are believed to have occurred in mid-December. The vulnerability was identified by Ivanti after the Ivanti Integrity Checker Tool (ICT) revealed the presence of malware on users’ appliances. The malware was installed after a threat actor exploited a previously unknown remote code execution flaw, which is being tracked as CVE-2025-0282 and has a CVSS severity score of 9.0. The critical stack buffer overflow flaw affects all Ivanti Connect Secure (Pulse Secure) VPN appliances running versions 22.7R2 through 22.7R2.5, Ivanti Policy Secure versions 22.7R1 through 22.7R1.2, and Ivanti Neurons for ZTA Gateways versions 22.7R2 through 22.7R2.3, although to date, the flaw only appears to have been exploited to compromise Ivanti Connect Secure appliances. A second stack buffer overflow flaw has also been patched, although it is not currently being exploited....
Eastern Idaho Public Health Discovers Insider Data Breach
Eastern Idaho Public Health has discovered an insider data breach, Pacific Pulmonary Medical Group has identified unauthorized access to its scheduling software, and Ingham County Medical Care Facility (Dobie Road) said patient data was accessed in a security incident at its electronic health records portal manager. Eastern Idaho Public Health Discovers Insider Data Breach Eastern Idaho Public Health has started notifying certain patients that one of its former employees has accessed their medical records without authorization. When unauthorized access to medical records was suspected, a review was conducted of the employee’s access logs and interviews were conducted with staff members. The employee was discovered to have viewed patient records, specifically patient clinic notes. The information potentially viewed included health screening information, patient histories, assessments, orders, and test results. Eastern Idaho Public Health was able to confirm that copies of the records had not been made and Eastern Idaho Public Health is confident that the information in the medical...
Billing Support Vendor Notifies 701K Patients About December 2023 Data Breach
Medusind, a Florida-based revenue cycle management vendor and practice management software provider, has recently started notifying individuals about a security breach detected more than a year ago. According to the notification letters, the unauthorized access occurred on December 23, 2023, and was detected and blocked the same day. A third-party cybersecurity firm was engaged to investigate the breach, and evidence was found of data exfiltration. The review of the affected files has now been completed, and notification letters have been mailed. Medusind is offering the affected individuals two years of complimentary credit monitoring and identity theft protection services. Information potentially compromised in the incident includes health insurance and billing information, debit/credit card numbers or bank account information, health information such as medical history, medical record number, or prescription information, government identification such as Social Security number, taxpayer ID, driver’s license number, or passport number), and other personal information such as date...
OCR Resolves Multiple Security Rule Failures with USR Holdings with $337,750 Settlement
It has been a busy end to the year for the HHS’ Office for Civil Rights (OCR) concerning HIPAA enforcement. By mid-December, OCR had announced 16 settlements and civil monetary penalties to resolve alleged violations of the HIPAA Rules; however, OCR Director Melanie Fontes Rainer announced in her end-of-year wrap-up of OCR accomplishments that there had been 22 HIPAA enforcement actions last year, three of which were announced this week. Earlier this week, OCR announced two settlements to resolve ransomware-related investigations that uncovered risk analysis failures – an $80,000 settlement with Elgon Information Systems and a $90,000 settlement with Virtual Private Network Solutions. On January 8, 2025, OCR announced that a $337,750 settlement had been agreed with the Florida business associate, USR Holdings, LLC, to resolve multiple alleged violations of the HIPAA Security Rule. USR Holdings is a holding company that owns and manages primary mental health and substance abuse treatment facilities in Florida, Maryland, and Kentucky. In its capacity as a HIPAA business...



